bug(import): Bedrock Agent import fails on multi-action-group agents and missing gateway proxy Lambda
- Dominant language
- TypeScript
- Stars
- 283
- Forks
- 95
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 183
Description
## Description
Customers migrating Bedrock Agents to AgentCore via the `import-agent` flow hit two distinct, reproducible failures. Both were originally reported against the Python starter toolkit (`bedrock-agentcore-starter-toolkit`), but since the AgentCore CLI (`@aws/agentcore`) is now the recommended migration tool, we should confirm the equivalent code paths here are correct and covered by tests.
Source: SIM V2200635700 / AWS Support Case 177764821500904 (ELLUCIAN, us-east-1). Agents: `BI13NJQLYA` (Megamind_Dev), `514OLCKKBT` (Crowdstrike), `U8V6BP3CRL` (Ask_Ellucian, imports fine).
### Bug 1 — Action-group translation crashes with `'str' object has no attribute 'get'`
Agents with multiple action groups fail to translate even with `--disable-gateway`. Root cause in the starter toolkit: the code assumes `actionGroup["apiSchema"]` is always a dict, but the Bedrock Agent API returns it as a raw string for OpenAPI-hosted action groups.
- 0 action groups → imports fine
- 4 action groups → fails
The equivalent CLI path is `fetchActionGroups()` in `src/cli/aws/bedrock-import.ts` (~L218), where `apiSchema.payload` is assumed to be an object. We should verify string / S3 / missing-payload shapes are all handled without throwing.
### Bug 2 — Gateway proxy Lambda is never created
With the default (gateway-enabled) migration, `CreateGatewayTarget` fails with:
```
ValidationException: Lambda function not found:
arn:aws:lambda:us-east-1::function:gateway_proxy_
```
CloudTrail showed **zero** `CreateFunction` calls during import — the tool references a dynamically-named proxy Lambda without ever creating it. Confirm whether the CLI's gateway-target codegen for imported agents creates (or documents the need to create) the proxy Lambda, rather than referencing a name that doesn't exist.
## Steps to Reproduce
1. Have a Bedrock Agent with 4+ action groups (some using OpenAPI/inline `apiSchema`).
2. `agentcore import-agent --region us-east-1 --agent-id 514OLCKKBT --agent-alias-id LPPXEL2IK2 --target-platform strands --disable-gateway --output-dir out`
→ **Bug 1**: `Failed to translate agent! Error: 'str' object has no attribute 'get'`
3. Run the same import **without** `--disable-gateway`
→ **Bug 2**: `CreateGatewayTarget ... Lambda function not found: gateway_proxy_`
## Expected Behavior
- Action groups with string / S3 / inline `apiSchema` payloads translate without crashing.
- Gateway-enabled import either creates the required proxy Lambda or fails with a clear, actionable message.
## Actual Behavior
- Multi-action-group agents crash during translation.
- Gateway import references a non-existent proxy Lambda and fails.
## Additional Context
- Bug 1 confirmed independent of gateway (repros with `--disable-gateway`).
- Bug 2 blocks all default-gateway migrations for this account; IAM perms (`lambda:CreateFunction`, `lambda:InvokeFunction`) verified present.
- Starter-toolkit fix for a related symptom shipped in `bedrock-agentcore-starter-toolkit` 0.3.9 (PR aws/bedrock-agentcore-starter-toolkit#515); customer reported the `'str'...` error still reproduced after upgrade.
Contributor guide
Research direction
Start in src/cli/aws/bedrock-import.ts at fetchActionGroups() around line 218 and trace the gateway-target codegen path. Reproduce imports with string, S3, and missing-payload apiSchema shapes, then inspect the gateway-enabled flow for proxy Lambda creation. Done means both import modes handle the reported inputs without an unhandled exception and either create the proxy Lambda or report a clear actionable failure.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, typescript
- Domain
- cli, cloud
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100